Sophos Addresses Critical Firewall Vulnerabilities
In December 2024, Sophos, a leading cybersecurity firm, announced the resolution of three significant vulnerabilities in its firewall products. These vulnerabilities, identified as CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729, posed potential risks ranging from unauthorized access to remote code execution.
Details of the Vulnerabilities
- CVE-2024-12727: A pre-authentication SQL injection vulnerability in the email protection feature. This flaw could lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled alongside the firewall operating in High Availability (HA) mode. Approximately 0.05% of devices were affected by this issue. [Source]
- CVE-2024-12728: During the HA cluster setup, a suggested, non-random SSH login passphrase remained active post-establishment, potentially exposing a privileged system account if SSH was enabled. This vulnerability impacted about 0.5% of devices. [Source]
- CVE-2024-12729: A post-authentication code injection vulnerability in the User Portal allowed authenticated users to achieve remote code execution. [Source]
Remediation and Recommendations
Sophos promptly released hotfixes for the affected versions. For customers with the "Allow automatic installation of hotfixes" feature enabled (the default setting), no manual action was required. However, users operating on older, unsupported versions were advised to upgrade to receive the latest protections.
To mitigate potential risks, Sophos recommended:
- Ensuring SSH access is restricted to only the dedicated HA link that is physically separate.
- Reconfiguring HA using a sufficiently long and random custom passphrase.
- Disabling WAN access via SSH by following device access best practices and utilizing VPN or Sophos Central for remote access and management.
Conclusion
While there have been no reports of these vulnerabilities being exploited in the wild, Sophos emphasized the importance of applying updates and adhering to recommended security practices to safeguard systems against potential threats.
Sources
- Sophos Security Advisory: Resolved Multiple Vulnerabilities in Sophos Firewall
- SecurityWeek: Sophos Patches Critical Firewall Vulnerabilities
- Heise Online: Critical vulnerabilities threaten Sophos firewalls
- BleepingComputer: Sophos discloses critical Firewall remote code execution flaw
- The Hacker News: Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation